deep-dive

iCloud Private Relay: What It Protects and What It Doesn't

Private Relay hides your browsing from ISPs and websites but leaves iCloud data fully accessible to Apple. Here's what it actually does and doesn't do.

Apple markets iCloud Private Relay as a privacy feature that obscures your identity and browsing from network observers. It does do that, in a specific, technically interesting way. What it does not do — and what the name implies to many users — is provide any meaningful protection for the files, photos, and personal data you store in iCloud itself.

Understanding the difference matters, because Private Relay and iCloud’s data privacy are questions that pull in opposite directions. One is about hiding your browsing from your internet provider. The other is about whether Apple can read your files. Conflating the two leads to a false sense of security about the data that actually matters most.


What Private Relay Actually Does

iCloud Private Relay is a privacy proxy service included with paid iCloud+ subscriptions. It routes Safari web traffic and DNS queries through two separate relays — one operated by Apple and one operated by a third-party partner — with the goal that no single entity can see both who you are and what you are browsing.

The mechanism works like this: your device sends its IP address and identity to Apple’s first relay, which knows who you are but cannot see the destination site. Apple’s relay then passes your traffic to a third-party relay with a temporary anonymous IP address; that relay can see the destination site but not your identity. The destination website sees only the third-party relay’s IP, not your real address.

This protects against a specific threat model: your internet service provider monitoring your browsing history, websites building cross-site profiles from your IP address, and network-level eavesdropping on your unencrypted DNS queries.

It is genuinely useful for the problem it solves. ISPs in several countries have broad authority to collect and sell browsing data. IP-based tracking is a widespread and effective technique for linking your behavior across websites. Private Relay disrupts both.


What Private Relay Does Not Do

Private Relay operates at the network layer, on outgoing web traffic. It has no relationship to the contents of your iCloud account.

Your photos in iCloud, documents in iCloud Drive, notes in iCloud Notes, contacts, calendar events, device backups — none of these are affected by Private Relay in any way. The privacy properties of these stored items are governed by iCloud’s encryption model, which is a separate and more complicated topic.

Private Relay does not encrypt your iCloud storage. The photos in your iCloud library are encrypted in transit (when they travel between your device and Apple’s servers) and encrypted at rest on Apple’s servers. But the keys for that encryption are held by Apple, not you. Apple can read your photos. So can a government that serves Apple with a legal order.

Private Relay does not protect against Apple. The whole system depends on Apple operating one of the two relays. Apple knows your identity (your Apple ID and IP) when you enter the Private Relay pipeline. Apple’s stated design is that it is architecturally prevented from seeing your destination, but Apple’s infrastructure is still the gatekeeper for your traffic.

Private Relay does not work in all situations. It only applies to Safari traffic. Third-party browsers, apps that make their own network calls, VPN connections (Private Relay is disabled when a VPN is active), and networks that block it (including many corporate and government networks) do not go through Private Relay.

Private Relay does not work everywhere. Due to regulatory requirements, Apple disables Private Relay in certain countries, including China, Belarus, Colombia, Egypt, Kazakhstan, Saudi Arabia, South Africa, Turkmenistan, Uganda, and the Philippines. In these regions, your network traffic is not routed through Private Relay regardless of your iCloud+ subscription.


iCloud Encryption: The Actual Privacy Question for Your Data

The privacy of the files and data you store in iCloud is determined by iCloud’s encryption model, not Private Relay. This is worth understanding in some detail because the model has important implications for what Apple can access.

Standard iCloud Encryption

By default, iCloud encrypts your data in transit and at rest. Apple holds the encryption keys for most categories of iCloud data. The practical consequence: Apple can decrypt and read your Photos, Drive files, email, contacts, calendars, notes, reminders, and most other iCloud-stored data. This is required for features like Siri integration, search indexing, and iCloud.com web access, all of which need the server to process your data.

When Apple receives a legal order — a subpoena, court order, or national security letter — it can and does provide user data it has the keys to decrypt. Apple publishes transparency reports showing the volume of government requests it receives and responds to.

Advanced Data Protection

Apple introduced Advanced Data Protection (ADP) as an opt-in feature that extends end-to-end encryption to most iCloud data categories, including iCloud Drive, Photos, Notes, Reminders, and device backups. With ADP enabled, Apple holds no decryption keys for those categories — even Apple cannot read the contents, and legal orders to Apple cannot compel production of data Apple cannot decrypt.

ADP represents a genuinely different privacy posture from standard iCloud encryption. It is not the default, however. You must explicitly enable it, and doing so comes with a practical trade-off: Apple support cannot help you recover access if you lose all your trusted devices and recovery contacts, because Apple has no key to give you.

What ADP Does Not Cover

Even with Advanced Data Protection enabled, several data categories remain under standard encryption where Apple holds keys: iCloud Mail, Contacts, Calendars, and data from third-party iCloud-connected apps. The rationale is that these categories require server-side processing (interoperability with external mail servers, for example) that is incompatible with client-side encryption.


The UK Situation

In early 2024, the United Kingdom government demanded that Apple build a backdoor providing authorities access to iCloud data encrypted under Advanced Data Protection. Rather than comply, Apple chose to withdraw ADP availability for UK users entirely. UK users on iCloud cannot enable Advanced Data Protection; their iCloud data is covered by standard encryption with Apple holding keys.

This is a real limitation with real consequences for UK residents who care about the privacy of their stored files. It also illustrates the broader tension between cloud storage privacy and legal access frameworks — a tension that no cloud service, regardless of its stated privacy posture, is immune from if it operates in jurisdictions that have the power to compel backdoors.


Private Relay vs. a VPN

Users frequently ask how Private Relay compares to using a VPN. They solve different problems with different trade-offs.

A VPN routes all your device traffic through a provider’s servers, masking your real IP from every destination and encrypting your traffic from your device to the VPN server. A VPN provider sees your identity and your full traffic; in exchange for that trust, you get network-level privacy from your ISP and destination sites. VPN effectiveness depends entirely on the trustworthiness and jurisdiction of the VPN provider.

Private Relay routes Safari traffic through Apple’s infrastructure using a split architecture designed so that no single party sees both your identity and your destination. It does not route all traffic, only affects Safari, and Apple is not a neutral relay — Apple’s first relay sees your identity and Apple has commercial incentives and government obligations that differ from those of a dedicated VPN provider.

Neither is unequivocally better. Private Relay is simpler and requires no additional subscription; a VPN gives broader traffic coverage and removes Apple from the equation. Both are meaningful improvements over sending traffic without any obfuscation. Neither addresses what happens to data you actively store in a cloud service.


Why the Conflation Matters

Privacy marketing encourages bundling distinct features under a single reassuring concept. “Private” in the product name suggests that your iCloud experience is private — that what you store there is protected from outside eyes.

For browsing traffic in Safari, that is reasonably accurate with caveats. For the photos, documents, and files you store in iCloud, it is not accurate by default, and depends on a feature most users have never heard of, let alone enabled.

The practical consequence: people who believe iCloud is a “private” cloud because they have Private Relay enabled may store sensitive files — medical documents, financial records, private correspondence — with more confidence than the actual encryption model warrants. Apple can read those files. Governments can compel Apple to produce them.

This is not a reason to avoid iCloud. It is a reason to understand what you are storing and under what terms. If the contents of your iCloud storage need to be genuinely inaccessible to Apple, enabling Advanced Data Protection (where available) is the mechanism for achieving that. Private Relay is a different feature solving a different problem.


Evaluating Cloud Services Honestly

The iCloud Private Relay story is a useful frame for evaluating any cloud storage service’s privacy claims. The questions worth asking are:

What does the service encrypt, and who holds the keys? Encryption at rest with provider-held keys protects against storage breaches but not against legal orders or provider access. Client-side or end-to-end encryption means the provider cannot read your data regardless of legal pressure — but comes with recovery trade-offs.

What data does the service analyze? A service can store encrypted files without analyzing them, or it can run content recognition, AI training, and feature pipelines on your files. These are different products with different privacy properties.

Where is the service incorporated, and under what legal framework? Provider jurisdiction determines what laws govern legal data access requests. Swiss, EU, and US companies each face different legal environments.

Does the privacy marketing describe the actual model? Features that sound like privacy protections sometimes operate only at one layer. Understanding what each feature actually covers, rather than what the name suggests, leads to better decisions about what to store where.

daftei does not hold decryption keys for your files in the way that gives Apple — or a government order to Apple — access to iCloud data under standard encryption. Files stored in daftei are encrypted in transit with TLS 1.3 and at rest with AES-256. The service does not run content analysis on your stored files, does not train AI on your data, and does not sell data. For users who want a cloud storage layer that does not build AI profiles from their content, understanding these distinctions is the starting point.


Practical Checklist

If you use iCloud and care about the privacy of your stored data, here is a practical checklist:

  • Enable Advanced Data Protection in your Apple ID settings if you are in a country where it is available. This extends end-to-end encryption to iCloud Drive, Photos, and device backups.
  • Understand what ADP does not cover: iCloud Mail, Contacts, and Calendars remain under standard encryption even with ADP enabled.
  • Private Relay is not a storage-privacy feature. Enabling it does not change the encryption model for your iCloud files.
  • Set up recovery contacts or a recovery key before enabling ADP. Without a recovery mechanism, losing access to all your trusted devices permanently locks you out of your data.
  • Consider what you actually store in iCloud. Items you would be uncomfortable with Apple having access to — under legal compulsion or otherwise — belong either in ADP-covered categories or in a different service.

The name “Private Relay” describes the feature accurately: it is a relay that provides privacy at the network level. The private cloud storage you might be imagining is a different thing, available through a different mechanism, and not on by default.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts